Data location
Control plane, execution environments, code, and artifacts run where you deploy them. Connected model endpoints decide where request data travels — map each route. See data residency.
Official product guides and resources for MonkeyCode.
DEPLOYMENT SCENARIO · VERIFIED 2026-08-05
Teams in finance, healthcare, and the public sector adopt AI coding under obligations most tools were not designed around: data residency, auditability, retention, and vendor risk. A self-hostable, open-source platform puts those controls on your side of the boundary — this page maps which ones, what evidence to produce, and what remains your responsibility. Nothing here is a certification or legal advice.
Why self-hostable matters here
Available is not automatic: every control below still has to be configured, tested, and evidenced in your deployment.
Control plane, execution environments, code, and artifacts run where you deploy them. Connected model endpoints decide where request data travels — map each route. See data residency.
Outbound allowlists, network segmentation, and — where required — fully air-gapped operation are yours to enforce and monitor.
Per-task execution logs, review gates, and credential records support the audit trail regulators expect. See architecture and trust boundaries.
AGPL-3.0 source availability lets your security team inspect what runs. Obligations for modification or network service need qualified legal review.
Evidence pack
Produce these from your own deployment; no vendor page can supply them for you.
Every boundary — source control, model endpoints, packages, logs, backups — with owner, credential, retention rule, and allowed path. Start from security and data-flow boundaries.
Scope, expiry, and rotation for every credential an agent task can observe, with the revocation drill rehearsed.
Which actions require human approval — merges, deployments, dependency changes — and the log showing gates were enforced.
A reproducible record of tasks, outcomes, review effort, and failures from a bounded pilot, using the pilot methodology and open dataset schema.
Regulatory context
These are engineering-focused analyses with sources and limits — not legal counsel.
Which obligations reach AI coding-tool use, by role and date. Read the timeline.
Keeping proprietary code private across tool categories, and governing unsanctioned use. Data-governance guide · shadow AI.
Copyright of AI-generated code and AGPL-3.0 compliance questions to review with counsel. Ownership analysis · AGPL guide.
OWASP-aligned controls for agents that execute code, and lessons from a disclosed agent-run intrusion. OWASP checklist · incident analysis.
Common questions
Related: proprietary code safety, external transmission, self-hosting privacy.